Systems and methods for publishing and using images of dns zone configurations
Abstract
Systems and methods for publishing and using images of domain name system (DNS) zone configurations are described. An image file containing a copy of some or all of the DNS records associated with a zone DNS server (e.g., a DNS server for a zone) may be stored in a repository. In response to detecting that the zone DNS server is unavailable, an image server system retrieves the image file and stores the image file in an image DNS server. The image server system notifies a higher-level DNS server that the image DNS server is a DNS server for the zone. In some examples, the image file includes a zone signing key (ZSK) associated with the image DNS server that is signed by a key signing key (KSK) associated with the zone DNS server. The image DNS server uses the signed ZSK to sign DNS records for subsequent authentication.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method, comprising:
detecting, by an image server system, that a zone domain name system (DNS) server associated with a zone is unavailable; and in response to detecting that the zone DNS server is unavailable:
retrieving, from a repository, an image file comprising a set of DNS records associated with the zone DNS server,
storing the image file on an image DNS server of the image server system, and
transmitting, to a higher-level DNS server, an indication that the image DNS server is a DNS server for the zone.
2 . The method of claim 1 , further comprising:
receiving, at the image server system from a DNS resolver, an indication of a requested domain name in the zone; and in response to receiving the indication of the requested domain name:
identifying, in the image file stored on the image DNS server, an IP address based on the requested domain name, and
transmitting, to the DNS resolver, the IP address.
3 . The method of claim 1 , wherein the set of DNS records map domain names of the zone to corresponding IP addresses.
4 . The method of claim 1 , wherein one or more DNS records of the set of DNS records has been cryptographically signed for subsequent authentication.
5 . The method of claim 1 , wherein the image file comprises a signed zone-signing key (ZSK) associated with the image DNS server, wherein the signed ZSK is cryptographically signed by a key-signing key (KSK) associated with the zone DNS server, the method further comprising:
determining, by the image server system, that a first DNS record of the set of DNS records needs to be cryptographically signed; and in response to the determination that the first DNS record needs to be signed, cryptographically signing the first DNS record with the signed ZSK.
6 . The method of claim 5 , wherein determining that the first DNS record needs to be cryptographically signed includes receiving, from a DNS resolver, a request for the first DNS record, the method further comprising:
transmitting the cryptographically signed first DNS record to the DNS resolver.
7 . The method of claim 5 , wherein determining that the first DNS record needs to be cryptographically signed includes determining that an IP address associated with the first DNS record has changed from a first IP address to a second IP address; and
in response to the determination that the IP address has changed:
updating the IP address of the first DNS record from the first IP address to the second IP address to generate an updated first DNS record.
8 . The method of claim 1 , wherein the image file comprises an indication of allowable transfers from other zones.
9 . The method of claim 1 , further comprising:
transmitting, to the higher-level DNS server, expiration information associated with the indication that the image DNS server is the DNS server for the zone.
10 . The method of claim 1 , wherein detecting that the zone DNS server is unavailable comprises:
determining, by the image server system, that a response time of the zone DNS server exceeds a threshold latency.
11 . The method of claim 1 , wherein detecting that the zone DNS server is unavailable comprises:
receiving a notification from an external computing device.
12 . The method of claim 1 , wherein the set of DNS records includes a start of authority (SOA) record.
13 . The method of claim 1 , wherein the higher-level DNS server is a top-level domain (TLD) DNS server or a root DNS server.
14 . A system, comprising:
at least one processor; and memory, storing instructions that, when executed by the at least one processor, cause the system to perform a method, the method comprising:
detecting that a zone domain name system (DNS) server associated with a zone is unavailable; and
in response to detecting that the zone DNS server is unavailable:
retrieving, from a repository, an image file comprising a set of DNS records associated with the zone DNS server,
storing the image file on an image DNS server of the system, and
transmitting, to a higher-level DNS server, an indication that the image DNS server is a DNS server for the zone.
15 . The system of claim 14 , wherein the method further comprises:
receiving, from a DNS resolver, an indication of a requested domain name in the zone; and in response to receiving the indication of the requested domain name:
identifying, in the image file on the image DNS server, an IP address based on the requested domain name, and
transmitting, to the DNS resolver, the IP address.
16 . The system of claim 14 , wherein the set of DNS records map domain names of the zone to corresponding IP addresses.
17 . The system of claim 14 , wherein one or more DNS records of the set of DNS records has been cryptographically signed for authenticating the respective DNS record.
18 . The system of claim 14 , wherein the image file comprises a signed zone-signing key (ZSK) associated with the image DNS server, wherein the signed ZSK is cryptographically signed by a key-signing key (KSK) associated with the zone DNS server, the method further comprising:
determining that a first DNS record of the set of DNS records needs to be cryptographically signed; and in response to the determination that the first DNS record needs to be cryptographically signed, cryptographically signing the first DNS record with the signed ZSK.
19 . The system of claim 18 , wherein determining that the first DNS record needs to be cryptographically signed includes receiving, from a DNS resolver, a request for the first DNS record, the method further comprising:
transmitting the cryptographically signed first DNS record to the DNS resolver.
20 . A method performed at an image server system, the method comprising:
detecting that a zone domain name system (DNS) server associated with a zone is unavailable; and in response to detecting that the zone DNS server is unavailable:
retrieving, from a repository, an image file comprising a set of DNS records associated with the zone DNS server,
retrieving a signed zone-signing key (ZSK) associated with an image DNS server of the image server system, wherein the signed ZSK is cryptographically signed by a key-signing key (KSK) associated with the zone DNS server,
storing the image file and the signed ZSK on the image DNS server, and
transmitting, to a higher-level DNS server, an indication that the image DNS server is a DNS server for the zone;
after storing the image file and the signed ZSK on the image DNS server, determining that a first DNS record of the set of DNS records needs to be cryptographically signed; in response to the determination that the first DNS record needs to be cryptographically signed, cryptographically signing the first DNS record with the signed ZSK; and transmitting the cryptographically signed first DNS record to a DNS resolver.Join the waitlist — get patent alerts
Track US2025193149A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.